Back to skill

Security audit

Book Museum Passes & Tickets — Museum Entry, Exhibition Access, Gallery Tours & Culture Passes

Security checks for vulnerabilities and agentic risk

Overview

This museum-ticket skill needs review because it automatically installs a global third-party CLI, forces booking-link outputs, and quietly persists raw user queries locally in an unsafe way.

Install only after review or revision. Require explicit approval before any package installation, avoid global unpinned npm installs, disable or redact local logs, and understand that the skill is designed to steer results through flyai booking links rather than neutral museum sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:10
Finding

Forced Commercial Output and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:37
Finding

Mandatory Installation of an Unpinned Global npm Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/runbook.md:34
Finding

Shell Command Injection Through Generated Execution Log Data

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The documented logging process inserts generated JSON into a single-quoted shell command. The JSON contains the raw user query as well as generated command and status fields. JSON encoding and shell escaping are different operations. A single quote in attacker-controlled input terminates the shell’s single-quoted string. The remainder can then be parsed as shell syntax. Consequently, a malicious query can inject command separators, redirections, substitutions, or arbitrary commands when the agent follows the prescribed persistence command. For example, a raw query shaped like the following could break out of the quoted argument: ```text ' ; attacker_command ; echo ' ``` The exact exploit payload depends on the shell and generated JSON, but the underlying quote-boundary violation is present in the documented cons ...[truncated 1237 chars]
Remediation
View remediation

other

Warning
Location
references/runbook.md:3
Finding

Undisclosed Persistence of Raw User Queries

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The runbook directs the agent to retain the complete raw user query and detailed execution history in `.flyai-execution-log.json`. It explicitly states that this internal logging is not shown to users. Travel-related queries can contain location, itinerary, identity, timing, and preference information. The instructions provide no consent mechanism, data minimization, redaction, retention period, deletion process, access-control requirement, or maximum file size. Appending records causes sensitive history to accumulate across executions. Although the filename is dot-prefixed, that does not provide access control or encryption. ### Attack Path 1. A user submits a query containing travel plans, location information, or other sensitive detail ...[truncated 985 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

flyai search-poi --city-name "Beijing" --category "博物馆"

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill also supports flight booking, hotel reservation, train tickets, itinerary planning, visa info, travel insurance, car rental, and more. But the rest of the file defines activation, parameters, workflows, and examples only for museum, gallery, exhibition, and memorial searches via flyai search-poi, with no documented commands or logic for those broader travel functions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description claims support for broad travel-booking tasks far beyond museum discovery, which can cause the agent to invoke this skill for unrelated requests. In this skill's context, that is risky because the workflow pushes mandatory CLI execution and package installation, so over-broad routing expands the situations in which those side effects may occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to install a global npm package automatically, which modifies the host environment and executes code from an external registry without prior user confirmation or risk disclosure. In an agent setting, this creates a supply-chain and integrity risk because a simple content query can trigger package installation on the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prerequisites direct a global npm install with no warning that this changes the system and runs third-party code. Because the skill is intended for automatic activation, this increases the chance that unreviewed dependency installation occurs in response to benign travel queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The mandatory workflow says to check for the CLI and automatically install it if missing, making environment modification part of normal query handling. This is dangerous because it turns an informational user request into implicit code execution and package installation, increasing exposure to supply-chain compromise and unauthorized system changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The commands embed Chinese category labels like "博物馆", "展览馆", and "纪念馆" while the surrounding playbook is in English. This imposes a specific language/locale choice without stating that the skill is Chinese-locale-specific or offering the user a language option.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "memorial" is broad and ambiguous, so the skill may activate for unrelated user requests involving memorials, remembrance, or non-museum contexts. In a tool-routing setting, this can cause unintended command execution or irrelevant travel-search behavior, increasing the chance of misfires and incorrect downstream actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The runbook explicitly records the raw user_query in an internal execution log, but provides no notice, minimization, or retention controls. Because this skill handles travel-related tasks that may involve personal, financial, itinerary, or visa-related details, storing raw input creates avoidable privacy exposure if logs are accessed, retained too long, or reused outside the user's expectations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Taken together, the schema stores raw user_query data and then appends the resulting log to a persistent local file, creating a complete path from sensitive input to durable storage. In the context of a travel assistant that may collect names, destinations, booking details, visa questions, or other personal data, this materially increases privacy and data-handling risk from disclosure, accidental sharing, or forensic recovery.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest declares the skill as museum-pass, but the body header labels it museum-guide. This is not just omitted detail; it suggests inconsistent intent about whether the skill is a booking/pass tool or a guide/search tool, which can mislead an agent about the skill's purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The runbook instructs the agent to append execution logs to a local file whenever filesystem writes are available, but gives no warning or safeguards around local persistence. Even if intended for debugging, silent local writes can leave sensitive traces on shared hosts, developer machines, or containers where users do not expect their requests to be stored.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.